RETIRED: Multiple Vendors IMAP Servers Denial of Service Vulnerability
BID:31318
Info
RETIRED: Multiple Vendors IMAP Servers Denial of Service Vulnerability
| Bugtraq ID: | 31318 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2008 12:00AM |
| Updated: | Sep 30 2008 02:29PM |
| Credit: | Jeremy Brown |
| Vulnerable: |
University of Washington imapd 0 GNU Mailutils 0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Carnegie Mellon University Cyrus IMAP Server 0 |
| Not Vulnerable: | |
Discussion
RETIRED: Multiple Vendors IMAP Servers Denial of Service Vulnerability
Multiple vendors' IMAP servers are prone to a remote denial-of-service vulnerability caused by an unspecified error when handling IMAP login requests.
An attacker can exploit this issue to make the affected applications unresponsive, denying service to legitimate users.
This issue affects:
University of Washington imapd
Carnegie Mellon University Cyrus IMAP Server
GNU Mailutils imapd
NOTE: Reports indicate that this issue arises when the affected serves are used with the Debian Sarge platform. Therefore these issues may affect only Debian-specific instances. We will update this BID as more information emerges.
UPDATE: The issue is being retired because it has been determined not to be a vulnerability.
Multiple vendors' IMAP servers are prone to a remote denial-of-service vulnerability caused by an unspecified error when handling IMAP login requests.
An attacker can exploit this issue to make the affected applications unresponsive, denying service to legitimate users.
This issue affects:
University of Washington imapd
Carnegie Mellon University Cyrus IMAP Server
GNU Mailutils imapd
NOTE: Reports indicate that this issue arises when the affected serves are used with the Debian Sarge platform. Therefore these issues may affect only Debian-specific instances. We will update this BID as more information emerges.
UPDATE: The issue is being retired because it has been determined not to be a vulnerability.
Exploit / POC
RETIRED: Multiple Vendors IMAP Servers Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
RETIRED: Multiple Vendors IMAP Servers Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Multiple Vendors IMAP Servers Denial of Service Vulnerability
References:
References:
- Cyrus IMAPD Home Page (Carnegie Mellon University)
- Debian Homepage (Debian)
- GNU Mailutils (GNU)
- IMAP Information Center (University of Washington)